Re: Theory Question

From: Jacques A. Vidrine (n@nectar.com)
Date: 04/08/01


Date: Sat, 7 Apr 2001 18:00:40 -0500
From: "Jacques A. Vidrine" <n@nectar.com>
To: John Howie <JHowie@msn.com>

On Sat, Apr 07, 2001 at 03:48:53PM -0700, John Howie wrote:
> Agreed! And the hacker would also need to have intimate knowledge of your
> network configuration to be able to supply the correct parameters to
> ifconfig in the scenario that Crist outlined.

Well, no. Arbitrary code is just that: arbitrary. Arbitrary code can
determine a working configuration for any network interface. And in
many cases it will not even be necessary to `ifconfig' the interface
to use it.

> One item that was missing from
> the original design was an exterior DMZ firewall (or perhaps I just missed
> that component) running NAT. Key to securing the infrastructure is making it
> as difficult as possible for a hacker to determine DMZ and production
> network topologies and machine addresses.

If the `key' to your security is obscurity of your internal network
configuration, expect to be comprimised. This information is not hard
to obtain by a determined attacker, and technology is probably not
even an issue.

Cheers,

-- 
Jacques Vidrine / n@nectar.com / jvidrine@verio.net / nectar@FreeBSD.org
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: Remote Access and Outlook Web Access on SBS 2003
    ... that's how the *Wizard* configured your network. ... NETWORKING CONFIGURATION SUMMARY ... Restrict default Web site of IIS to only respond to ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Access and Outlook Web Access on SBS 2003
    ... SUMMARY OF SETTINGS FOR CONFIGURE E-MAIL AND INTERNET ... Internet Connection Wizard. ... network, firewall, secure Web site, and e-mail. ... NETWORKING CONFIGURATION SUMMARY ...
    (microsoft.public.windows.server.sbs)
  • Re: A little FYI
    ... > fix for a different problem or end up making the same configuration ... Maybe faulty network equipment, ... > to look at what might interfere with DHCP. ... you were not here as I was trying to get the card to stay ...
    (comp.security.firewalls)
  • Re: Windows 2K3 and Virtual Server 2005 guests NAT problem
    ... The first thing to check is that you have configured NAT correctly. ... internal network. ... in seeing the actual configuration and what your settings are. ... If you have configured DNS on the host and have set your vms to use ...
    (microsoft.public.windows.server.networking)
  • Re: DC/DNS/DFS/AD Problem???
    ... Windows IP Configuration ... Here is the ipconfig for another server in the network. ... Is there a tool that would test DFS because on a scale of 1 ...
    (microsoft.public.windows.server.networking)

Quantcast